top of page

New Safeguarding Information-Sharing Duty: What Schools Need to Know Before 30 September 2026

1 day ago
6 min read

Schools have always needed to share information when it is necessary to safeguard children.

But from 30 September 2026, the legal framework around safeguarding information sharing in England is changing.

A new statutory Information Sharing Duty, introduced through the Children’s Wellbeing and Schools Act 2026 and section 16LA of the Children Act 2004, comes into force.

The Department for Education published its final statutory guidance on 10 September 2026, alongside new template data-sharing agreements.

For headteachers, DSLs, SENCOs, School Business Managers and DPOs, this is an important change.

The key message is straightforward:

Data protection should enable appropriate safeguarding information sharing – not become a reason for failing to share information when a child may need help.

But that does not mean schools should share information indiscriminately.

Here is what schools need to know.


What is changing on 30 September?

The new Information Sharing Duty places a clearer legal expectation on relevant organisations and practitioners to share information where it is relevant to safeguarding or promoting the welfare of a child and where sharing may help another relevant organisation carry out its safeguarding or welfare functions.

The DfE says the guidance is intended to support more consistent information sharing across organisations and encourage a cultural shift in how safeguarding information is shared. It applies across education as well as local authorities, health, police, early years and other relevant services.

This matters because effective safeguarding often depends on different organisations seeing different pieces of the same picture.

A school may know about deteriorating attendance.

Social care may know about difficulties at home.

Health professionals may hold another piece of information.

Individually, those pieces might not appear decisive. Together, they may reveal that a child needs support or protection.


Does this mean schools can ignore GDPR when safeguarding?

No.

This is perhaps the most important point for schools to understand.


The new duty does not remove data-protection responsibilities.


Schools still need to handle personal information lawfully, securely and proportionately.

What changes is the strength and clarity of the legal expectation around appropriate safeguarding information sharing.

The question should therefore not simply be:

“Are we allowed to share this under GDPR?”

A better approach is:

“Is this information relevant to safeguarding or promoting this child’s welfare, could sharing it help the receiving organisation perform its safeguarding functions, and is the proposed sharing appropriate?”


Schools should not allow an overly cautious interpretation of data protection to prevent legitimate safeguarding action.

Equally, “safeguarding” should never become a blanket justification for unnecessary or excessive sharing.


What information could be covered?

Safeguarding information can extend considerably beyond information about an immediate child-protection incident.


Depending on the circumstances, relevant information might concern:

  • attendance or persistent absence

  • changes in behaviour

  • unexplained injuries

  • concerns about neglect

  • domestic abuse

  • mental health or emotional wellbeing

  • exploitation

  • online harm

  • family circumstances

  • SEND or health needs

  • previous safeguarding concerns

  • information about another individual connected to the child.


The legislation is deliberately concerned with information that may be relevant to safeguarding or promoting a child’s welfare.

That is significant because safeguarding does not always begin with certainty. Information sharing can help agencies understand emerging concerns and build a fuller picture.


What about consent?


This is an area where schools can understandably become nervous.

Consent is not the only basis on which personal information can be shared.

Schools should not assume that they must always obtain parental consent before sharing safeguarding information.

Equally, that does not mean children and families should routinely be kept in the dark.

The appropriate approach will depend on the circumstances, including the nature of the information, why it is being shared, the legal basis for processing it and whether telling someone about the disclosure could create additional risk.

This is exactly why DSL and DPO roles should complement rather than compete with one another.

The DSL brings the safeguarding judgement.

The DPO helps ensure that the information is processed lawfully and appropriately.


Does every school need a new data-sharing agreement?


Not necessarily.


The DfE has published two template multi-agency data-sharing agreements alongside the new guidance: a strategic Tier 1 template and an operational Tier 2 template.

Importantly, the DfE describes these as starting points for local adaptation or for updating existing local agreements.

So schools should not immediately replace every existing agreement.


Instead, ask:

What information-sharing arrangements do we already have, and do they remain appropriate under the new framework?


For trusts, this may also be a good opportunity to check whether schools are using consistent approaches rather than each setting developing its own arrangements independently.


Seven things schools should do before 30 September


There is no need to turn this into an enormous compliance project.A sensible September review should cover seven things.


1. Brief your DSL and safeguarding team

Make sure those making safeguarding decisions know that the new statutory duty comes into force on 30 September.


2. Review your safeguarding procedures

Check whether your safeguarding and child-protection procedures accurately explain when and how information may be shared.


3. Review your data-protection guidance

Look for wording that could inadvertently discourage legitimate safeguarding disclosures – particularly blanket statements suggesting information cannot be shared without consent.


4. Check your recording arrangements

Staff should be able to record what information was shared, with whom, why it was shared and the professional judgement behind the decision.

Good recording protects the child, the practitioner and the school.


5. Review existing data-sharing agreements

Do not automatically replace them. Compare current arrangements with the new DfE guidance and templates and identify any genuine gaps.


6. Include the change in staff safeguarding updates

Staff do not need to become GDPR specialists.

They do need to understand that a genuine safeguarding concern should be reported through the school’s safeguarding process rather than withheld because they are worried about “breaking GDPR”.


7. Bring your DSL and DPO together

Information governance and safeguarding should support each other.

Where a complex case arises, early discussion between the DSL and DPO can help the school reach a defensible decision without unnecessarily delaying safeguarding action.


A simple test for schools


When deciding whether safeguarding information needs to be shared, it can help to work through a simple sequence:


What information do we hold?

Why could it be relevant to safeguarding or promoting this child’s welfare?

Could sharing it help the receiving organisation carry out its safeguarding or welfare functions?

Is there any reason why sharing would create greater detriment to the child?

What information actually needs to be shared?

Who genuinely needs to receive it?

How will we share it securely?

Have we recorded our decision and reasoning?



That is a much more useful approach than starting with “GDPR says we can’t share it.”

What should governors and trustees know?

Governors and trustees do not need to make individual information-sharing decisions.

They should, however, have assurance that the school or trust has appropriate arrangements in place.

A useful question for a governing body or trust board this term would be:


“Has the school reviewed its safeguarding information-sharing arrangements following the new statutory duty coming into force on 30 September 2026?”


The answer should be capable of being evidenced through policies, procedures, staff awareness and appropriate information-governance arrangements.


The bigger lesson: GDPR should not be a barrier to safeguarding


There has long been tension in some organisations between protecting confidentiality and sharing information to protect children.

Often, the problem is not the law itself.

It is uncertainty about the law.

The new statutory duty is intended to provide greater clarity and confidence across safeguarding organisations. The Government has specifically identified poor information sharing as a factor in serious safeguarding incidents and has sought to strengthen multi-agency working through the Children’s Wellbeing and Schools Act.

For schools, the aim should therefore be neither “share everything” nor “share nothing without consent.”

It should be:

Share the right information, with the right people, for the right safeguarding purpose – and record why you did it.

That is good safeguarding and good information governance.


Useful official guidance


Department for Education – Information sharing to safeguard children and young people

Full URL:


This page contains the final statutory guidance and the two new DfE template data-sharing agreements.


Department for Education – Information Sharing Duty consultation outcome

Full URL:


This includes the Government’s response to the consultation and explains the development of the new framework.


Children’s Wellbeing and Schools Act 2026 – explanatory notes

Full URL:


This explains the legislation introducing section 16LA and the Information Sharing Duty.


Need help reviewing your school’s information-sharing arrangements?


SchoolDPO supports schools, academies and trusts with practical data protection and information-governance advice – including safeguarding information sharing, data-sharing agreements, DPIAs, breaches, SARs, policies and staff guidance.


Thinking about changing your DPO? If you’re looking for a responsive, school-focused Data Protection Officer who understands education – not just legislation – we’d be delighted to help.

 
 
 

Recent Posts

See All

Comments


DPO member
INCENSU Logo

Follow us on Linked IN

  • Linkedin

Contact us

School DPO
bottom of page